Vulnerabilities > CVE-2018-7855 - Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a Denial of Service when sending invalid breakpoint parameters to the controller over Modbus
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Talos
id | TALOS-2019-0766 |
last seen | 2019-06-10 |
published | 2019-06-10 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0766 |
title | Schneider Electric Modicon M580 UMAS set breakpoint denial-of-service vulnerability |
References
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/
- https://www.schneider-electric.com/en/download/document/SEVD-2019-134-11/
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0766
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0766
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0767
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0767